CVE-2021-34593

Severity
7.5HIGH
EPSS
1.6%
top 18.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 26
Latest updateMay 24

Description

In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages16 packages

NVDcodesys/runtime_toolkit< 2.4.7.56
NVDcodesys/plcwinnt< 2.4.7.56
CVEListV5codesys/codesys_v2Runtime Toolkit 32 bit fullV2.4.7.56+1

🔴Vulnerability Details

2
GHSA
GHSA-mp42-p5v3-r5p6: In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V22022-05-24
CVEList
CODESYS V2 runtime: unauthenticated invalid requests may result in denial-of-service2021-10-26
CVE-2021-34593 (HIGH CVSS 7.5) | In CODESYS V2 Runtime Toolkit 32 Bi | cvebase.io